
Russian‑linked group targets hotel Wi‑Fi to steal Microsoft 365 tokens
Microsoft ties a global hospitality Wi‑Fi campaign to the Russian group Midnight Blizzard (Storm-2945), detailing DNS tampering and two malware families, CornFlake and ChocoShell, used to steal Microsoft 365 tokens and credentials via phishing, device-code prompts, and fake update pages; researchers urge treating hotel Wi‑Fi as untrusted, using MFA/passkeys, and avoiding corporate credentials on guest networks.








